Chamilo

Chamilo Lms

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 10.04.2026 19:16:24
  • Zuletzt bearbeitet 16.04.2026 18:23:31

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET /api/users, including administrator accou...

  • EPSS 0.03%
  • Veröffentlicht 10.04.2026 19:16:24
  • Zuletzt bearbeitet 16.04.2026 18:22:09

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2....

  • EPSS 0.03%
  • Veröffentlicht 10.04.2026 19:16:23
  • Zuletzt bearbeitet 16.04.2026 18:27:48

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change their status to Teacher/CourseMana...

  • EPSS 0.07%
  • Veröffentlicht 10.04.2026 19:16:23
  • Zuletzt bearbeitet 16.04.2026 18:25:38

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email...

  • EPSS 0.04%
  • Veröffentlicht 10.04.2026 18:32:45
  • Zuletzt bearbeitet 16.04.2026 18:29:46

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable ...

  • EPSS 0.22%
  • Veröffentlicht 10.04.2026 18:30:48
  • Zuletzt bearbeitet 16.04.2026 18:34:15

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body be...

  • EPSS 0.04%
  • Veröffentlicht 10.04.2026 18:23:01
  • Zuletzt bearbeitet 16.04.2026 18:48:04

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API token...

  • EPSS 0.03%
  • Veröffentlicht 10.04.2026 18:15:49
  • Zuletzt bearbeitet 16.04.2026 18:48:21

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file lp_ajax_save_item.php accepts a uid (u...

  • EPSS 0.05%
  • Veröffentlicht 10.04.2026 18:14:17
  • Zuletzt bearbeitet 16.04.2026 18:48:33

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by...

  • EPSS 0.05%
  • Veröffentlicht 10.04.2026 18:10:16
  • Zuletzt bearbeitet 17.04.2026 22:03:07

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1...